Your number was almost certainly not stolen by a hacker. It leaked out of a company you gave it to — or a vendor that company hired — was bundled into a list sorted by category, and sold cheaply. In India's largest reported case, police said the buyers were "marketing and advertising companies. Some were cybercriminals." A Noida call centre bought roughly 10,000 people's details for ₹2,500 — about 25 paise a head. Your recourse today is TRAI's complaint system (within 7 days), Sanchar Saathi for fraud, and written erasure requests to the companies still holding the record.
A telecaller rings. He has your full name. He knows which bank you use, or that your child wrote NEET this year, or that you enquired about a flat in a particular locality six months ago. It does not feel like a cold call. It feels like someone told him.
Someone did. Not a person who knows you — a list.
Most Indian writing on this topic is either dark-web mythology or a shrug: "your data is out there." Neither is useful. What follows is the route your number actually takes, reconstructed from police statements, arrest records and government documents. Where the evidence runs out, this post says so.
Stage 1 — The handover
Start with the honest part. There is no published Indian case that says "the lucky-draw box at the mall sold your number." We are not going to invent one, and you should be suspicious of any article that does.
What exists is the police inventory — the list of what investigators actually found being sold. In the April 2023 Cyberabad case, ThePrint reported that the data was sorted into 104 categories including debit and credit card holders, frequent flyers, demat account holders, PAN card holders, NEET students, senior citizens and electricity consumers.
Read that list backwards and you get the collection points: a bank, a card application, a broking account, an exam form, a utility connection. Every category is somewhere a real person handed over real details for a real reason. That is a reasoned inference from a published inventory — not a documented case — and we're labelling it as such.
Which makes the practical question narrower and more useful: which of those handovers did you actually owe? Two are worth knowing about.
The shop does not need your number for the bill
No GST invoicing rule requires your mobile number. Under Rule 46(f) of the CGST Rules 2017, for a sale under ₹50,000 to an unregistered buyer, even your name and address go on the invoice only if you ask for them. A phone number appears nowhere in the required fields, at any value. "Sir, bill ke liye number chahiye" is a CRM request wearing a compliance costume.
Being forced to share data to complete a purchase is a named dark pattern
India's Guidelines for Prevention and Regulation of Dark Patterns, 2023 list "forced action" — described in Annexure I as forcing users "to purchase additional goods, or subscribe to unrelated services, or share their personal information to buy the product or service they originally wanted." The Guidelines themselves note these illustrations are guidance rather than a binding opinion, and enforcement so far has centred on pricing and cart practices, not billing-counter phone numbers (AZB & Partners). Still: if a checkout will not proceed without a number unrelated to the purchase, that is a consumer-law question as well as a privacy one.
Stage 2 — The escape
Here the evidence gets much stronger, and it points somewhere uncomfortable: the leak point is usually a company you trusted, or a vendor that company hired.
After the April 2023 arrest, Cyberabad Police served notices on eleven organisations whose customer data had turned up in the haul — described by Business Today as three banks, a social media giant, an IT services company, an online grocery seller, a digital payments app and an online insurance platform. Police asked them to explain how their databases were maintained, what policies were followed, and who could access the data.
Important: that was an investigative step, not a finding of liability. No company on that list was charged over it. The publishable point is the ordinariness of the list — these are apps you already have on your phone.
Cyberabad police also described the usual route into the market. In bank data theft cases, they said, the data is often leaked through the third-party companies banks hire to verify their customers' details (ThePrint). Not the bank being hacked. The bank's outsourcing layer.
That pattern has kept repeating. In August 2025, The Tribune reported that police in Haryana had arrested 18 people over a credit-card fraud of nearly ₹2.60 crore that began with insider moles at an authorised card-protection call centre in Gurugram, who siphoned off confidential SBI credit-card data. The fraudsters then rang cardholders posing as bank staff. The customers had done nothing wrong — they had given their details to their bank, and their bank had given them to a vendor.
Sometimes the "leak" is not a leak at all. In July 2026, Noida police busted two fraudulent call centres whose operators, according to Business Today, "sourced job seekers' contact details from online employment portals" before offering fake airline recruitment. No hacking required — just a resume with a phone number on it. The accused were charged under the Bharatiya Nyaya Sanhita along with Section 66D of the IT Act.
Why nobody told you
You have probably never received an email saying "your data was exposed." There is a structural reason for that.
Since directions issued in April 2022 (in force from that June), Indian companies have had to report data breaches and data leaks to CERT-In within six hours (CERT-In direction under s.70B(6)). That is a duty owed to the government. It produces no notice to you.
The rule that requires a company to tell you — Rule 7 of the DPDP Rules 2025 — sits inside the block of rules that commence eighteen months after the November 2025 gazette. It is not enforceable yet. Until then, most Indians will learn about a breach from a scam call, not an email. (More on the timeline in what to do after a data breach in India.)
Stage 3 — The aggregation
This is the stage that explains why the caller knows something true about you.
On 1 April 2023, Cyberabad Police arrested a man in Faridabad, Haryana, saying he had procured and was selling the personal data of 66.9 crore individuals and organisations across 24 states and eight metros, in 104 categories (The South First). Two other men, named as his suppliers, were still being sought at the time of reporting.
A week earlier, the same police unit had announced a separate bust: a gang trading the data of 16.8 crore citizens in more than 140 categories. MediaNama reported that the arrested men "primarily worked as data entry operators and tele-callers," and that investigators suspected the mobile numbers of about 3 crore of those individuals had been leaked from telecom service providers. Suspected — not established.
The word to hold onto is categories. Nobody bought your number. Someone bought "demat account holders" or "NEET students" or "credit card applicants," and you were in that file. The caller is not guessing and did not research you. He bought a segment.
That is also why blocking numbers never ends it, and why unsubscribing from one caller does nothing about the next. The list has already been copied. If a caller seems to know your bank specifically, that has its own explanation — see why the caller knows which bank you use.
What it costs: about 25 paise a head
The prices are the part that reframes everything.
| Case | What police said it sold for |
|---|---|
| Cyberabad, April 2023 — 66.9 crore records | Some datasets "for as low as Rs 2,000"; the accused had sold data worth less than ₹1 lakh in total |
| Noida, July 2024 — fake loan/insurance call centre | Details of about 10,000 people for ₹2,500 — roughly 25 paise per person |
Cyberabad's Deputy Commissioner of Police said the arrested man had sold data worth under ₹1 lakh, and described him as one link in a larger chain (Deccan Chronicle). In the Noida case, Outlook reported that eleven people were arrested — including nine women hired as telecallers — after police found the operation had bought data on about 10,000 people for ₹2,500 and had been running for over a year.
Twenty-five paise is what it costs to buy the right to call you. Your data is cheap precisely because it is everywhere — which is also why nobody in the chain has any incentive to be careful with it.
Who buys it: mostly marketing companies
This is the single most useful sentence in the entire public record on Indian data trading, and it comes from a police officer rather than a privacy campaigner. Speaking about the buyers of the 66.9 crore dataset, Cyberabad's DCP said the accused sold information to "about 50 clients and they were marketing and advertising companies. Some were cybercriminals" (ThePrint).
Marketing first. Criminals as the minority.
That reorders the whole problem. The primary output of India's stolen-data economy is not fraud — it is the ordinary sales call. The fraud rides on the same lists.
It was not the dark web. It was a business directory.
The gang arrested in March 2023 did not need a hidden marketplace to find buyers. NewsMeter reported that enquiries placed through an ordinary business-listing service — people asking for sector-wise contact data — were routed to them as though they were a legitimate listed vendor. They operated through ordinary-sounding registered company names, out of call centres.
Written strictly in the past tense: that is how far this trade had normalised by 2023. It was being conducted through the same channels businesses use to buy any other service, by people whose day job title was "data entry operator" or "tele-caller."
You cannot avoid this market by staying off shady websites, because it was never on shady websites.
What this article will not do — deliberately. We will not name a marketplace, a channel, a forum or a seller. We will not describe how any of this is searched for, bought or accessed, and we will not reproduce a single leaked record. Every price and figure above is an aggregate already published by police or mainstream Indian media. If an article claims to show you "where your data is being sold" by pointing at a live source, that article is a shopping guide, not a privacy guide.
Why arrests don't end it
India is good at arrests and poor at endings.
Between 2020 and 2022, 1.67 lakh cybercrime cases were registered across 28 states and just 2,706 persons were convicted — a ratio of about 1.6% — according to NCRB data reported by The Tribune. In 2021 the figure was 490 persons.
In the largest case, the two men named as the accused's suppliers were reported absconding at the time of the arrest, and no conviction has been publicly reported in either of the two 2023 Cyberabad cases since. That is an absence of reported evidence, not proof that nobody was convicted — Indian trial outcomes are frequently never reported, and we did not search court records.
The practical conclusion is not despair. It is that your remedy cannot depend on someone else being convicted. The removal route does not.
Your actual recourse, ranked
Report the call properly — within 7 days
Under TRAI's Second Amendment Regulations, 2025, a complaint made more than seven days after the call is closed and recorded as a mere "report" — it can no longer trigger action. A complaint is treated as valid if it carries four things: the sender's number, your number, the date, and a brief description. And the threshold that matters: if five or more unique recipients complain about the same sender within ten days, the operator must suspend that sender's outgoing services and investigate. Your complaint is one of five required votes, not a personal grievance. Use the TRAI DND app — it pre-fills the fields from your call log. How to report a spam call properly →
Use the right door for fraud
A pushy loan or property call is a TRAI matter. A call impersonating your bank, the police or a courier is a fraud attempt — report it on the Chakshu facility at Sanchar Saathi. If money has already left your account, skip both and call 1930 immediately; the portal itself routes financial-loss cases there.
Reduce the number of companies holding the record
This is the only step that touches the actual supply. Delete accounts you no longer use. Set job-portal profiles to recruiter-only visibility and remove old resumes. Check where your number is already listed across Indian platforms — start with our list of Indian data brokers and the broker directory, or run a phone exposure check. Also worth knowing whether your number has appeared in a known breach.
Send written erasure requests — and be honest about the timeline
Section 12 of the DPDP Act 2023 gives you a right to erasure of personal data you gave a company by consent, and requires the company to erase it "unless retention of the same is necessary for the specified purpose or for compliance with any law." Two honest caveats. First, the rights chapter and the enforcement machinery commence on an eighteen-month clock from the November 2025 notification — around mid-May 2027 (PIB). Second, the right attaches to data you gave the company; it is doubtful it reaches a broker who bought or scraped your details and never had your consent at all. Send the request anyway, in writing, to the company's grievance officer — many comply, and a dated request is the record every later escalation is built on.
If a company's negligence leaked you, there is a compensation window closing
The DPDP Act pays you nothing: its penalties go to the Consolidated Fund of India, and it creates no jail term at all. The one provision that pays money to a data-breach victim is Section 43A of the IT Act — and DPDP s.44(2)(a) omits it. That repeal commences with the same eighteen-month phase, so the route is open only until roughly mid-May 2027, through an Adjudicating Officer rather than a civil court. If you are considering it, gather evidence now and take advice from a qualified lawyer — this is a summary, not legal advice.
For the criminal side, prosecutions are built on IT Act s.66 (which requires proving the act was dishonest or fraudulent) and s.72A (which catches the insider who disclosed data in breach of a lawful contract), alongside cheating and conspiracy offences. And if the caller is a bank's sales agent, remember the bank remains answerable: RBI's 2006 outsourcing guidelines require that "the bank should seek to ensure the preservation and protection of the security and confidentiality of customer information in the custody or possession of the service provider." Escalate to the brand, not the telecaller.
The one conclusion every stage points to
Trace any of these routes and they end in the same place: a record sitting inside a company's database, waiting to leak again. A blocked number does not touch it. A DND registration does not touch it. A conviction — which almost never arrives — does not touch it.
Deletion at source is the only step that removes the thing being sold.
Find out which companies still hold your number
Saaph scans Indian platforms and known breach lists for your name, number and email, shows you exactly where you're exposed, and sends DPDP erasure requests to each holder. We can't stop a telecaller from dialling — we can shrink the list he bought from.
Run a free scan →FAQ
Who buys stolen personal data in India?
Cyberabad's DCP said the seller of the 66.9 crore dataset had about 50 clients and that they were "marketing and advertising companies. Some were cybercriminals." Marketing firms were the main buyers; criminals were the minority.
How much does my phone number sell for?
In bulk, almost nothing. Police said some datasets sold for as low as ₹2,000, and a Noida call centre had bought about 10,000 people's details for ₹2,500 — roughly 25 paise a person.
Is selling personal data a crime in India?
The DPDP Act 2023 has no imprisonment provision — it is a civil-penalty law, and its penalty chapter is not yet in force. Criminal cases are assembled from IT Act ss.66 and 72A and offences under the Bharatiya Nyaya Sanhita, each of which requires proving intent.
Why does the caller know something true about me?
Because the lists are sorted by category. Police inventories in the 2023 cases spanned 104 and 140+ categories — card holders, demat account holders, NEET students, senior citizens. The buyer chose a segment; you were in the file.
Will complaining actually do anything?
Individually, rarely. Structurally, yes — TRAI's rules require suspension of a sender's outgoing services once five unique recipients complain within ten days. Complain within seven days, with the caller's number and the date, or the complaint is closed.
General information as of August 2026. Figures and quotations are attributed to police statements and published reporting linked inline; arrests are not convictions, and no company named or described here has been found liable. Indian law and TRAI procedures change — Saaph.in does not provide legal advice. For cyber-fraud emergencies, call 1930 or visit cybercrime.gov.in.